The usual use of the zero-day term is for vulnerabilities that are being exploited while there is no fix yet (for a supported/current version). That is something the administrator cannot do much about. This vulnerability is probably already fixed...
Not sure what you mean by "Everything". So far you only reported your own single host being attacked.
Are you (by chance) connected to arjitc, the other reporter of this attack. (Interestingly both these users only joined today, for the purpose...
Only to you, unless you are claiming that it affects an up-to-date version of PVE.
PVE 7 is based on Debian 11, PVE 8 on Debian 12. So they would be affected by that bug unless they were updated since the bug was fixed.
In any case, I don't think this is a 0day vulnerability, because on this is happen due to out date servers and bad servers administration, to say the least.
Many of this vulnerabilities are well-know documented, such as kernel and ssh...
So, you are:
Running a OS that is EOL since two years
Exposing it to the internet
Disabling the firewall
If this is not a troll, I hope the lesson was learned...
I'll leave here the installation references for the steps needed for proxmox 9.2.11 using falcon-sensor_7.40.0-19311_amd64.deb
> apt install libnl-genl-3-200
Installing:
libnl-genl-3-200
Summary:
Upgrading: 0, Installing: 1, Removing: 0...
We are excited to announce the first release of Proxmox Virtual Environment with official support for a second CPU architecture: 64-bit ARM (arm64/aarch64). Until now, Proxmox VE was available for x86-64 (amd64) only.
Proxmox VE 9.2 for arm64...